CVE-2021-0060

Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101.0, SPS_SoC-A_05.00.03.114.0, SPS_SoC-X_04.00.04.326.0, SPS_SoC-X_03.00.03.117.0, IGN_E5_91.00.00.167.0, SPS_PHI_03.01.03.078.0 may allow an authenticated user to potentially enable escalation of privilege via physical access.

Published: 2022-02-09 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-0060 is rated Low Risk (34.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.32%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2021-0060

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.23% 0.32% +0.09%
2 2026-01-06 0.36% 0.23% -0.12%
3 2025-11-21 0.36%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-0060

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.6 3.1 MEDIUM
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:P)
Hands-on access—USB, keyboard, opening the case—not something you do purely over the wire.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.7 5.9 [email protected]
6.6 3.1 MEDIUM
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:P)
Hands-on access—USB, keyboard, opening the case—not something you do purely over the wire.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.7 5.9 134c704f-9b21-4f2e-91b3-4a467353bcc0
7.2 2.0 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.9 10.0 [email protected]

Weakness enumeration for CVE-2021-0060

Affected software / configurations for CVE-2021-0060

Vendor Product Version Raw CPE
intel c620a_series_firmware < sps_e5_04.04.03.281.0 cpe:2.3:o:intel:c620a_series_firmware:*:*:*:*:*:*:*:*
intel c620_series_firmware < sps_e5_04.01.04.516.0 cpe:2.3:o:intel:c620_series_firmware:*:*:*:*:*:*:*:*
intel c240_series_firmware < sps_e3_05.01.04.309.0 cpe:2.3:o:intel:c240_series_firmware:*:*:*:*:*:*:*:*
intel atom_p5000_series_firmware < sps_soc-a_05.00.03.114.0 cpe:2.3:o:intel:atom_p5000_series_firmware:*:*:*:*:*:*:*:*
intel atom_c3000_series_firmware < sps_soc-a_04.00.04.501.0 cpe:2.3:o:intel:atom_c3000_series_firmware:*:*:*:*:*:*:*:*
intel atom_c610_series_firmware < sps_phi_03.01.03.078.0 cpe:2.3:o:intel:atom_c610_series_firmware:*:*:*:*:*:*:*:*
intel xeon_d-1500_series_firmware < sps_soc-x_03.00.03.117.0 cpe:2.3:o:intel:xeon_d-1500_series_firmware:*:*:*:*:*:*:*:*
intel xeon_d_2000_series_firmware < sps_phi_03.01.03.078.0 cpe:2.3:o:intel:xeon_d_2000_series_firmware:*:*:*:*:*:*:*:*
intel 11th_generation_core_series_firmware < csme_15.0.35 cpe:2.3:o:intel:11th_generation_core_series_firmware:*:*:*:*:*:*:*:*
intel xeon_w-1300_series_firmware < csme_15.0.35 cpe:2.3:o:intel:xeon_w-1300_series_firmware:*:*:*:*:*:*:*:*
intel pentium_gold_series_firmware < csme_15.0.35 cpe:2.3:o:intel:pentium_gold_series_firmware:*:*:*:*:*:*:*:*
intel celeron_6000_series_firmware < csme_15.0.35 cpe:2.3:o:intel:celeron_6000_series_firmware:*:*:*:*:*:*:*:*
netapp cloud_backup cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
netapp hci_compute_node_bios cpe:2.3:o:netapp:hci_compute_node_bios:-:*:*:*:*:*:*:*
netapp hci_storage_node_bios cpe:2.3:o:netapp:hci_storage_node_bios:-:*:*:*:*:*:*:*
netapp solidfire_bios cpe:2.3:o:netapp:solidfire_bios:-:*:*:*:*:*:*:*

References for CVE-2021-0060

cvelogic Threat Intelligence